<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-73487</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:05:18+09:00</news:publication_date>
      <news:title>CVE-2026-73487 Flowise の Python コード検証を正規表現で迂回でき、未認証の予測 API 経由でプロンプトインジェクションからコード実行に至る（3.1.3 未満）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-19478</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:05:18+09:00</news:publication_date>
      <news:title>CVE-2026-19478 GitLab CE/EE の GraphQL ディレクティブ経由で、未認証ユーザーが公開プロジェクトとユーザーデータを改変・削除できる（18.11.11 / 19.0.8 / 19.1.6 / 19.2.4 で修正）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-49869</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:13:51+09:00</news:publication_date>
      <news:title>CVE-2026-49869 Kestra OSS の認証フィルタが末尾一致で判定、末尾が configs のパスすべてで認証を素通りし未認証RCEに至る（1.0.45 / 1.3.21 で修正・KEV 期限 2026-09-05）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-59822</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T20:13:51+09:00</news:publication_date>
      <news:title>CVE-2026-59822 LiteLLM の MCP エンドポイントで認証が素通りする、偽の Authorization ヘッダで未認証のまま MCP ツールへ到達（1.84.0 で修正・KEV 収載）</news:title>
    </news:news>
  </url>
</urlset>